CVE-2025-21614 Details
Description
go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.
A denial-of-service vulnerability has been identified in go-git versions prior to 5.13. This issue allows an attacker to cause resource exhaustion in go-git clients by sending specially crafted responses from a Git server. This vulnerability does not affect the upstream Git command-line interface.
Users of go-git version 4.0.0 prior to 5.13.0 should upgrade to version 5.13.0. If an immediate upgrade is not possible, it is recommended to limit the use of go-git to trusted Git servers.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/go-git/go-git/security/advisories/GHSA-r9px-m959-cxf4 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| go-git project go-git | < 5.13.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2025 | Modified Analysis | [email protected] |
| Aug 26, 2025 | CVE Modified | CISA-ADP |
| Apr 17, 2025 | Initial Analysis | [email protected] |
| Jan 6, 2025 | New CVE Received | [email protected] |
| Jan 6, 2025 | CVE Modified | CISA-ADP |